Impact
The DLL Services component in Mozilla Firefox can be abused to obtain privileges beyond those originally granted, enabling an attacker to perform privileged actions that compromise the integrity, confidentiality, and availability of the system. The weakness is fundamentally an improper privilege management flaw, specifically a privilege escalation scenario that allows lower-level processes or code to elevate their rights.
Affected Systems
This vulnerability affects Mozilla Firefox across both Extended Support Release (ESR) and regular versions. It was confirmed to have been fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. All releases older than these specific builds remain vulnerable.
Risk and Exploitability
The CVSS score of 8.8 classifies this vulnerability as high severity, while EPSS data is not available, leaving exploitation probability unknown. The flaw does not appear in the CISA KEV catalog, so no confirmed public exploitation has been reported. The likely attack vector, inferred from the nature of DLL Services, would involve local execution or manipulation of DLL loading to inject malicious code, although the precise conditions are not detailed in the description.
OpenCVE Enrichment